Hello,
A következőt szeretném:
Van egy subnetem (192.168.1.0), aminek a fenti router az átjárója.
Egy db ethernet port van rajta, amire szeretnék egy második subnetet felhúzni. Kb. így nézne ki:
gw--eth0---192.168.1.0/255.255.255.0
|
|
eth0:0 ?
|
\ 192.168.2.0/255.255.255.0
Lehet e ilyet ezzel az eszközzel illetve ha igen, akkor hogyan ?
Kulcsszavaknak is tudnék örülni :)
Köszönöm.
sh conf
!
version 12.3
no service pad
service timestamps debug datetime msec localtime show-timezone
service timestamps log datetime msec localtime show-timezone
service password-encryption
service sequence-numbers
!
hostname gw
!
boot-start-marker
boot-end-marker
!
logging buffered informational
!
no aaa new-model
ip subnet-zero
no ip source-route
ip name-server ---
ip name-server ---
!
no ip bootp server
ip cef
!
!
!
!
crypto isakmp policy 1
encr 3des
authentication pre-share
group 2
crypto isakmp key sss address 82.xxx.yyy.zzz no-xauth
!
!
crypto ipsec transform-set 3DES-SHA esp-3des esp-sha-hmac
crypto ipsec transform-set AES-SHA esp-aes esp-sha-hmac
crypto ipsec transform-set 3DES-SHA-compression esp-3des esp-sha-hmac comp-lzs
crypto ipsec transform-set AES-SHA-compression esp-aes esp-sha-hmac comp-lzs
!
crypto map VPN-Map-1 10 ipsec-isakmp
set peer 82.xxx.yyy.zzz
set transform-set 3DES-SHA
match address Crypto-list
!
!
!
interface Ethernet0
description $FW_INSIDE$
ip address 192.168.1.254 255.255.255.0
ip access-group 130 in
no ip redirects
no ip unreachables
no ip proxy-arp
ip nat inside
ip tcp adjust-mss 1412
no cdp enable
hold-queue 100 in
hold-queue 100 out
!
interface ATM0
no ip address
no ip redirects
no ip unreachables
no ip proxy-arp
no atm ilmi-keepalive
dsl operating-mode auto
crypto map VPN-Map-1
!
interface ATM0.1 point-to-point
description Layer2 connectivity
no ip redirects
no ip unreachables
no ip proxy-arp
pvc 1/32
pppoe-client dial-pool-number 1
!
!
interface Dialer1
description $FW_OUTSIDE$
ip address negotiated
ip access-group 120 in
no ip redirects
no ip unreachables
no ip proxy-arp
ip mtu 1452
ip nat outside
encapsulation ppp
ip tcp adjust-mss 1432
dialer pool 1
dialer-group 1
no cdp enable
ppp authentication chap pap callin
ppp chap hostname -----
ppp chap password -----
ppp pap sent-username ----- password -------
crypto map VPN-Map-1
!
ip nat inside source list 120 interface Dialer1 overload
ip nat inside source static tcp 192.168.1.10 10051 interface Dialer1 10051
ip nat inside source static tcp 192.168.1.10 9444 interface Dialer1 9444
ip nat inside source static tcp 192.168.1.9 636 interface Dialer1 636
ip nat inside source static tcp 192.168.1.9 25 interface Dialer1 25
ip nat inside source static tcp 192.168.1.8 1723 interface Dialer1 1723
ip nat inside source static udp 192.168.1.8 1194 interface Dialer1 1194
ip nat inside source static tcp 192.168.1.9 22 interface Dialer1 2222
ip nat inside source static tcp 192.168.1.253 22 interface Dialer1 22222
ip classless
ip route 0.0.0.0 0.0.0.0 Dialer1
ip route 192.168.2.0 255.255.255.0 82.144.183.65
no ip http server
no ip http secure-server
!
!
ip access-list extended Crypto-list
permit ip 192.168.1.0 0.0.0.255 192.168.2.0 0.0.0.255
ip access-list extended Crypto-list-1
permit ip 192.168.1.0 0.0.0.255 192.168.3.0 0.0.0.255
logging 192.168.1.8
access-list 120 deny ip 192.168.1.0 0.0.0.255 192.168.2.0 0.0.0.255
access-list 120 permit ip 192.168.1.0 0.0.0.255 any
access-list 120 permit ip any any
access-list 120 deny ip 192.168.1.0 0.0.0.255 192.168.3.0 0.0.0.255
access-list 130 remark internal net rules
access-list 130 permit tcp host 192.168.1.9 any eq smtp
access-list 130 deny tcp 192.168.1.0 0.0.0.255 any eq smtp log
access-list 130 permit ip any any
dialer-list 1 protocol ip permit
no cdp run
!
snmp-server community public RO 99
snmp-server enable traps tty
!
line con 0
stopbits 1
line vty 0 4
exec-timeout 2 0
password ------
login
transport preferred telnet
!
scheduler max-task-time 5000
end
- 859 megtekintés
Hozzászólások
sima masodik ip kell?
probald meg:
int e0
ip addr 192.168.2.0 255.255.255.0 sec
- A hozzászóláshoz be kell jelentkezni
Köszönöm, müxik :).
- A hozzászóláshoz be kell jelentkezni